पाठ 23 / 26

Deployment Security Checks

check --deploy.

Settings that must change for production

python manage.py check --deploy reviews settings for production: DEBUG must be False, ALLOWED_HOSTS set, a strong SECRET_KEY from the environment, HTTPS redirects and HSTS, secure session and CSRF cookies. Django also protects against CSRF, XSS (auto-escaping templates), SQL injection (parameterised ORM queries) and clickjacking by default; do not disable these protections without a strong reason. For FastAPI, configure CORS, HTTPS, and security headers explicitly.

Warnings for development settings, run

I ran this with Django 6.1.1 and Python 3.12 in a demo project (shopsite with a catalog app) using SQLite. Run on the freshly generated settings, the check reports 8 issues; the seven security warnings are shown, each trimmed to its first sentence.

python manage.py check --deploy

Output:

(security.W004) You have not set a value for the SECURE_HSTS_SECONDS setting.
(security.W008) Your SECURE_SSL_REDIRECT setting is not set to True.
(security.W009) Your SECRET_KEY has less than 50 characters, less than 5 unique characters, or it's prefixed with 'django-insecure-' indicating that it was generated automatically by Django.
(security.W012) SESSION_COOKIE_SECURE is not set to True.
(security.W016) You have 'django.middleware.csrf.CsrfViewMiddleware' in your MIDDLEWARE, but you have not set CSRF_COOKIE_SECURE to True.
(security.W018) You should not have DEBUG set to True in deployment.
(security.W020) ALLOWED_HOSTS must not be empty in deployment.
System check identified 8 issues (0 silenced).

Run check --deploy in CI

Running it against production settings in CI catches insecure configuration before release.

त्वरित जाँच: Which setting must be False in production?

  • DEBUG
  • USE_TZ
  • APPEND_SLASH
  • INSTALLED_APPS
Answer

DEBUG — Debug pages leak sensitive information.